{"id":311,"date":"2024-11-18T00:04:52","date_gmt":"2024-11-18T00:04:52","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/thomasgable\/?p=311"},"modified":"2024-11-18T00:04:52","modified_gmt":"2024-11-18T00:04:52","slug":"write-up-the-human-factor-in-cybersecurity","status":"publish","type":"post","link":"https:\/\/sites.wp.odu.edu\/thomasgable\/2024\/11\/18\/write-up-the-human-factor-in-cybersecurity\/","title":{"rendered":"Write Up &#8211; The Human Factor in Cybersecurity"},"content":{"rendered":"\n<p><em>In this write-up, I will act as a Chief Information Security Officer and talk specifically about how I would distribute limited funds between training and additional cybersecurity technology.<\/em><\/p>\n\n\n\n<p><strong>Brief Overview<\/strong><\/p>\n\n\n\n<p>Allocating funds for cybersecurity and IT within companies is very important and must be done correctly. There are really two main categories: Employee cybersecurity training and new cyber technologies. Each takes an extraneous amount of thought and planning to make the correct choices for the company in question. My job as a CISO is to ensure that there is a sensible balance between the two, attempting to reduce human error and uphold a sophisticated cyber defense system. <\/p>\n\n\n\n<p><strong>Employee Training<\/strong><\/p>\n\n\n\n<p>Stu Sjouwerman&#8217;s recent study revealed that \u201capproximately 88 percent of all data breaches are caused by an employee mistake.\u201d This statistic represents the importance of employee training within workplaces. Therefore, I would allocate approximately 35% of the Cyber funds given to me to staff training. Now, this may not seem like that much but the cost of new cyber technologies outweighs the cost of training materials, so it&#8217;s still a fairly substantial amount. A few specific items that I would spend this money on would be developing comprehensive policies, interactive simulations, educational resources, behavior-monitoring softwares, incident response drills, and possibly penetration tests. These would play a meaningful role in teaching employees how to identify and mitigate cyber threats, as well as ensuring they are understanding and taking these steps. As for employee training, I believe it is more time and effort than money, depending on the budget size. <\/p>\n\n\n\n<p><strong>New Cyber-Technologies <\/strong><\/p>\n\n\n\n<p>While poor employee training does play a large part in many data breaches, it\u2019s still very important to have updated and advanced cybersecurity tools. A lot of this software and hardware can cost a pretty penny, which is why I could allocate the other 65% of the funds to them. They often require subscriptions\/licenses, installation fees, maintenance costs, and configuration, which adds up. A few examples of new technologies that I would use this part of the budget on would include antivirus software, incident response, backup\/restoration, network security, and employee management. Investing in high-quality, robust technologies may be expensive, but will pay off in the long run.<\/p>\n\n\n\n<p><strong>Conclusion<\/strong><\/p>\n\n\n\n<p>Overall, both aspects of cybersecurity within companies are important but require different courses of action. As stated above, employee training can be more of a time and effort thing, whereas new technologies are where the big costs are. However, don\u2019t get it twisted, training staff still costs money and is very important. Investing in both is essential for businesses to create a well-developed cybersecurity defense.<\/p>\n\n\n\n<p><strong>References<\/strong><\/p>\n\n\n\n<ol>\n<li> Sjouwerman, S. (2024, May 9). Stanford Research: 88% Of Data Breaches Are Caused By Human Error. Stanford Research: 88% Of Data breaches Are Caused By Human Error. https:\/\/blog.knowbe4.com\/88-percent-of-data-breaches-are-caused-by-human-err or#:~:text=Researchers%20from%20Stanford%20University%20and,overwhelmi ng%20majority%20of%20cybersecurity%20problems.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>In this write-up, I will act as a Chief Information Security Officer and talk specifically about how I would distribute limited funds between training and additional cybersecurity technology. Brief Overview Allocating funds for cybersecurity and IT within companies is very important and must be done correctly. There are really two main categories: Employee cybersecurity training&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/thomasgable\/2024\/11\/18\/write-up-the-human-factor-in-cybersecurity\/\">Read More<\/a><\/div>\n","protected":false},"author":29481,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wds_primary_category":0},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/thomasgable\/wp-json\/wp\/v2\/posts\/311"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/thomasgable\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/thomasgable\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/thomasgable\/wp-json\/wp\/v2\/users\/29481"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/thomasgable\/wp-json\/wp\/v2\/comments?post=311"}],"version-history":[{"count":1,"href":"https:\/\/sites.wp.odu.edu\/thomasgable\/wp-json\/wp\/v2\/posts\/311\/revisions"}],"predecessor-version":[{"id":312,"href":"https:\/\/sites.wp.odu.edu\/thomasgable\/wp-json\/wp\/v2\/posts\/311\/revisions\/312"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/thomasgable\/wp-json\/wp\/v2\/media?parent=311"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/thomasgable\/wp-json\/wp\/v2\/categories?post=311"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/thomasgable\/wp-json\/wp\/v2\/tags?post=311"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}